Canary releases: Safeguards and recovery
Aborts a canary automatically when named error, latency, or saturation metrics breach soak-window thresholds, keeps sticky canary identity, and forbids silent promotion to full traffic.
Allows rollback only to a version that already passed health gates, requires a schema-compat check, and prefers roll-forward when irreversible data migration has already landed.